Reader small image

You're reading from  Mastering Microsoft Intune - Second Edition

Product typeBook
Published inMar 2024
PublisherPackt
ISBN-139781835468517
Edition2nd Edition
Right arrow
Authors (2):
Christiaan Brinkhoff
Christiaan Brinkhoff
author image
Christiaan Brinkhoff

Christiaan Brinkhoff works as a Principal Program Manager and Community Director for Windows 365 and AVD at Microsoft, in his role at Microsoft, he works on features such as Windows 11, Windows 365 app, Switch and Boot. Christiaan is also an Author (3 books) and Inventor (3 patents). His mission is to drive innovation while bringing Windows 365, Windows, and Microsoft Intune closer together, drive community efforts around virtualization to empower Microsoft customers in leveraging new cloud virtualization scenarios. Christiaan joined Microsoft in 2018 as part of the FSLogix acquisition. He has also been rewarded with the Microsoft MVP, Citrix CTP, and VMware vExpert community achievements - for his continued support in the EUC community.
Read more about Christiaan Brinkhoff

Per Larsen
Per Larsen
author image
Per Larsen

Per Larsen works as a Senior Program Manager for Microsoft Endpoint Manager - Customer Acceleration Team - Commercial Management Experiences (CMX) Engineering, where he takes learnings from Microsoft's largest and most strategic customers back into the rest of engineering to drive improvements for the service so that customers have a continuously improving product experience. He also helps deploy and adopt Microsoft Endpoint Manager - Microsoft Intune. Per mainly focuses on the management of Windows and special devices such as HoloLens 2, Surface Hub, and Microsoft Teams Room System. Per was also an MVP in Enterprise Mobility, from 1st July 2016 to when he joined Microsoft on 1st April 2018.
Read more about Per Larsen

View More author details
Right arrow

Cloud-Native Endpoints

The concept of cloud-native endpoints refers to devices that can be provisioned anywhere, cloud-native endpoints are devices that can be provisioned from anywhere and receive applications, policies, and maintenance updates throughout their lifetime from the cloud. You will learn about the concept of cloud-native endpoints and Zero Trust with Microsoft Intune, along with its history and architectural concepts, to get a clear understanding of how all devices – physical, virtual, and mobile – come together in a single management console.

In this chapter, we’ll go through the following topics:

  • What are cloud-native endpoints?
  • Microsoft Intune
  • Exploring Windows 11 Enterprise in detail
  • Windows Autopatch
  • Bring Your Own Device (BYOD)
  • What is Zero Trust?
  • Windows 365 for non-managed endpoints

Paths to cloud native

Modern management is a comprehensive approach to managing Windows devices in a consistent and unified way without compromising the security of endpoints. It involves the execution of strategies that equip IT to evolve the modern workplace into a space that is cherished by users, appreciated by IT, and trusted universally. The essence of modern management lies in cloud intelligence, which facilitates streamlined, contemporary management through cloud-based device management solutions like Microsoft 365.

The modern desktop is the state-of-the-art productivity platform for the information worker. Microsoft 365 apps and Windows 11 are the core components of the modern desktop along with the latest security baselines for Windows 11 and Microsoft Defender for Endpoint.

Since the first Windows 10 release back in 2015, Microsoft included the Mobile Device Management (MDM) stack natively built in, and along with that many companies have explored new management...

Microsoft Intune

What is unified endpoint management and how does this look through the concept of Microsoft Intune? The following high-level architecture drawing (Figure 2.2) explains how everything within Microsoft Intune comes together in one unified endpoint management experience.

There is one console for your physical and cloud PCs via Windows 365 endpoints and mobile devices. This is the only place where they can be managed in a unified way. Also, the Intune company portal can deploy apps from Configuration Manager, Intune, Windows 365, Azure Virtual Desktop, and Microsoft Entra ID – one end user experience for all apps!

High-level architectural diagram for Microsoft Intune

Figure 2.2: Microsoft Intune architecture diagram

The diagram of the Microsoft Intune architecture illustrates the three stages of the cloud management journey using Configuration Manager and Intune as a single, unified endpoint management solution:

  1. Tenant attach
  2. Co-management workloads
  3. Cloud-native management
  4. ...

Exploring Windows 11 Enterprise in detail

Some Windows features are exclusive to the Enterprise edition of Windows, while certain MDM capabilities are only available for Enterprise versions. Windows 11 Enterprise offers exclusive features and services on top of those available in Windows 11 Pro. Refer to the following list of additional Enterprise features and services:

  • Intelligent security:
    • Credential Guard: Protects against user credential harvesting and pass-the-hash attacks or pass-the-token attacks.
    • Managed Microsoft Defender Application Guard (MDAG) for Microsoft Edge: Isolates enterprise-defined untrusted sites with virtualization-based security from Windows, protecting your organization while users browse the internet.
    • PDE: Encrypts an individual’s content using Windows Hello for Business to link the encryption keys to user credentials.
    • Always-on VPN device tunnel: Advanced security capabilities to restrict the type...

BYOD

Depending on the Windows Stockkeeping Unit (SKU) like Home and Pro, there are different options for BYOD. All BYOD scenarios can take advantage of Windows 365 and Azure Virtual Desktop to access either a full desktop or a single application as a remote app.

Windows devices can also be registered with Entra ID to gain access to corporate resources such as email.

Enroll the device in Intune as a personally owned device (BYOD). If an administrator has configured autoenrollment (available with Entra ID Premium subscriptions), the user only has to enter their credentials once. Otherwise, they’ll have to enroll separately through MDM-only enrollment and re-enter their credentials.

Microsoft Intune management does not provide the same management capabilities on BYOD; not all Windows editions have the same MDM management setting built in:

Figure 2.17: Microsoft Intune endpoint support

Windows Enterprise has full management features, whereas both the Home...

What is zero trust?

In the past, when organizations created remote access to corporate networks, normally, access was enabled using a VPN connection either on a corporate-owned or a personally owned Windows device, only secured by an MFA token.

In today’s world, organizations need a security model that can adapt to the complexities of the modern environment, accommodate a mobile workforce, and protect people, devices, applications, and data wherever they are located. This is the essence of zero trust. Instead of assuming that everything behind the corporate firewall is safe, the zero trust model operates on the assumption of a breach and verifies each request as if it originated from an uncontrolled network. No matter where the request comes from or what resource it is trying to access, the zero trust model teaches us to “never trust, always verify.”

Verifying identity

The majority of security breaches today involve credential theft, and lapses in...

Windows 365 for non-managed endpoints

Windows 365 is used by many enterprises to secure their environment. All the data inside the cloud PC resides in the cloud and the remoting protocol connects the client to the cloud PC over a highly secure connection.

What about BYOD – unmanaged scenarios where you have no control over the local PC? Great news – as with Windows 365, you can block access completely from the outside with RDP redirections inside Microsoft Intune – cloud PCs are very convenient to connect to a corporate managed and secure cloud PC with Windows 10 or Windows 11 from an un-managed (zero-trusted) endpoint device.

Learn more about how Intune Suite and Windows 365 bring your BYOD zero-trust security to the next level in Chapter 11!

Summary

In this chapter, we’ve learned about the fundamentals of unified endpoint management, modern management, and how this relates to Microsoft Intune. We also went through the different concepts, services, and products around Windows 11 Enterprise and security-related aspects of zero trust.

In the next chapter, we’re going to talk about Windows 365 and explain this service more.

After this section, we’ll continue to take a deeper dive, as we are going to talk about the different endpoint scenarios and requirements in terms of what is needed to use Microsoft Intune.

Questions

  1. What license do you need for Windows Autopatch?
    1. Microsoft 365 E3
    2. Microsoft 365 E5
    3. Windows 10/11 Enterprise E3
  2. What is the main principle behind zero trust?
    1. Never trust, always verify.
    2. Always trust, never verify.

Answers

  1. Either A or B
  2. A

Further reading

If you want to learn more about modern management after reading this chapter, please use one of the following free online resources:

Learn more on Discord

To join the Discord community for this book – where you can share feedback, ask questions to the author, and learn about new releases – follow the QR code below:

https://packt.link/SecNet

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Microsoft Intune - Second Edition
Published in: Mar 2024Publisher: PacktISBN-13: 9781835468517
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime

Authors (2)

author image
Christiaan Brinkhoff

Christiaan Brinkhoff works as a Principal Program Manager and Community Director for Windows 365 and AVD at Microsoft, in his role at Microsoft, he works on features such as Windows 11, Windows 365 app, Switch and Boot. Christiaan is also an Author (3 books) and Inventor (3 patents). His mission is to drive innovation while bringing Windows 365, Windows, and Microsoft Intune closer together, drive community efforts around virtualization to empower Microsoft customers in leveraging new cloud virtualization scenarios. Christiaan joined Microsoft in 2018 as part of the FSLogix acquisition. He has also been rewarded with the Microsoft MVP, Citrix CTP, and VMware vExpert community achievements - for his continued support in the EUC community.
Read more about Christiaan Brinkhoff

author image
Per Larsen

Per Larsen works as a Senior Program Manager for Microsoft Endpoint Manager - Customer Acceleration Team - Commercial Management Experiences (CMX) Engineering, where he takes learnings from Microsoft's largest and most strategic customers back into the rest of engineering to drive improvements for the service so that customers have a continuously improving product experience. He also helps deploy and adopt Microsoft Endpoint Manager - Microsoft Intune. Per mainly focuses on the management of Windows and special devices such as HoloLens 2, Surface Hub, and Microsoft Teams Room System. Per was also an MVP in Enterprise Mobility, from 1st July 2016 to when he joined Microsoft on 1st April 2018.
Read more about Per Larsen